<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to disable http/https portal on vSec gateway? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3969#M101627</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dameon,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help, in this SK I have found the correct file to edit and stopped the http redirect.&lt;/P&gt;&lt;P&gt;Also I was able to find what was enabling the https portal. It was the visitor mode for vpn clients, once disabled the https was closed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Jul 2017 20:44:10 GMT</pubDate>
    <dc:creator>Thomas_Pereira</dc:creator>
    <dc:date>2017-07-06T20:44:10Z</dc:date>
    <item>
      <title>How to disable http/https portal on vSec gateway?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3962#M101620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have two Security Gateways under the same management server. We need to disable outside access to the web portal on the vSec gateway.&lt;/P&gt;&lt;P&gt;This traffic is accepted by an implied rule. We did disable every single implied rule on the smart dashboard and try to edit the implied rules file in the path $FWDIR/lib.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the ports 80 and 443 are still open.&lt;/P&gt;&lt;P&gt;How could disable the outside access to this service?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jul 2017 14:14:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3962#M101620</guid>
      <dc:creator>Thomas_Pereira</dc:creator>
      <dc:date>2017-07-05T14:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable http/https portal on vSec gateway?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3963#M101621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you say "disable outside access" There certainly shouldn't be an implied rule that allows outside access to your firewalls. You should have a rule in your policy that allows certain hosts to access your firewalls(ssh, webui, etc), but then have a stealth rule directly below that preventing all other source traffic from hitting your firewalls.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jul 2017 18:38:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3963#M101621</guid>
      <dc:creator>Jay_Jeffcoat</dc:creator>
      <dc:date>2017-07-05T18:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable http/https portal on vSec gateway?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3964#M101622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jay.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a stealth rule in place.&lt;/P&gt;&lt;P&gt;And in the log the traffic is being allowed by Implicit rule 0.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jul 2017 18:49:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3964#M101622</guid>
      <dc:creator>Thomas_Pereira</dc:creator>
      <dc:date>2017-07-05T18:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable http/https portal on vSec gateway?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3965#M101623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Can you be more specific on what you're describing as "outside" access? Also, please post details about the actual implied rule that it's hitting on&lt;/SPAN&gt;&lt;SPAN&gt;? Obviously something isn't making since, you stated you disabled every implied rule yet the traffic is still permitted&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jul 2017 21:57:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3965#M101623</guid>
      <dc:creator>Jay_Jeffcoat</dc:creator>
      <dc:date>2017-07-05T21:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable http/https portal on vSec gateway?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3966#M101624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"Outside" is the Internet. In Azure the vSec has two interfaces one internal and one external this last being the one that leads to the Internet. The goal is to limit the access to the internal interface.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jul 2017 10:12:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3966#M101624</guid>
      <dc:creator>Thomas_Pereira</dc:creator>
      <dc:date>2017-07-06T10:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable http/https portal on vSec gateway?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3967#M101625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rule 0 can also indicate a setting that has a portal function and that is controlled by a property. As an example the identity awareness captive portal will listen. On what ports and interfaces depends on your configuration. I suspect what you see is similar to this and I advise you check those settings. By default they will have "internal interfaces" but that may be less relevant for vSEC, depending on how you deployed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peter !!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jul 2017 13:44:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3967#M101625</guid>
      <dc:creator>Peter_Sandkuijl</dc:creator>
      <dc:date>2017-07-06T13:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable http/https portal on vSec gateway?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3968#M101626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Multiportal issue, I think.&lt;/P&gt;&lt;P&gt;Refer to the following SK:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105740&amp;amp;partition=Advanced&amp;amp;product=Security" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105740&amp;amp;partition=Advanced&amp;amp;product=Security"&gt;HTTP and HTTPS requests to external interfaces create implied rule 0 accepts in SmartView Tracker&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jul 2017 16:09:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3968#M101626</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-07-06T16:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable http/https portal on vSec gateway?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3969#M101627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dameon,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help, in this SK I have found the correct file to edit and stopped the http redirect.&lt;/P&gt;&lt;P&gt;Also I was able to find what was enabling the https portal. It was the visitor mode for vpn clients, once disabled the https was closed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jul 2017 20:44:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3969#M101627</guid>
      <dc:creator>Thomas_Pereira</dc:creator>
      <dc:date>2017-07-06T20:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable http/https portal on vSec gateway?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3970#M101628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are looking to disable WebUI completely, use "set web daemon-enable off"&lt;BR /&gt;Do not forget&amp;nbsp;"save config"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jul 2017 07:49:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-disable-http-https-portal-on-vSec-gateway/m-p/3970#M101628</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2017-07-07T07:49:28Z</dc:date>
    </item>
  </channel>
</rss>

